Shared ARIN authority for DNSSEC key-signing automation?

General discussions and other topics.
2 posts Page 1 of 1
by blakers » Thu Apr 04, 2013 10:29 am
Hi,

Phone-support suggested I post this question here, in order to get an answer from Sys Ops/Admin @ Sonic.

I have a Static/29 allocated from Sonic.

I run my own DNS server; fwiw, it's ISC BIND 9.9.2.

RDNS for my /29 has been delegated to my nameserver.

I've now DNSSEC-signed my DNS zones. The next step is to get my DS records submitted 'upstream'.

I'd ideally like to do that using DNSSEC automation tools such as those included in BIND9 or OpenDNSSEC.

My current registrar -- Namecheap/eNom -- does not currently support DNSSEC.

One option to do so is to switch registrars to GoDaddy, which supports DNSSEC key submission, but only (iiuc) automation when using their DNS Management, NOT my own as I currently do. And, I'm personally not a fan of GoDaddy. I.e., the solution's NOT ideal.

An additional option is to use ArinOnline's automated tool for DNSSEC submission:
@ https://www.arin.net/resources/dnssec/
...
Reverse DNS and DNSSEC Management at ARIN

ARIN provides delegation management tools to individually manage reverse DNS within IPv4 and IPv6 networks once your zones are DNSSEC-enabled. ARIN members may choose to DNSSEC-enable their reverse zones by submitting Delegation Signer (DS) Records to ARIN.
...
After creating the required ArinOnline account for my Organization & its various PointsOfContact, I've learned in a phone call with Arin Tech Support that those tools are only availble directly to end-users from Arin if MY allocation is >= /24 AND my ISP's allocation is <= /16. That's obviously not the case.

However ... on that same page, I was directed to:
@ https://www.arin.net/resources/dnssec/
...
Shared Authority

When ARIN-issued IP address space is reassigned by an organization to their customer, both parties may manage DNS for that space via Shared Whois Project (SWIP). Organizations with authority over a delegation are listed in the Authorized Organizations column.

Note: If your organization’s customers are disconnected from you, it is imperative that you protect your records by promptly removing any SWIPs to them, thus severing their shared authority rights for your reverse zones.
...
As I understand it, Sonic can 'share authority' for my allocated IP space, enabling me to piggyback on its direct ARIN relationship to use the ARIN DNSSEC tools/API for automated submission of my DNSSEC DS-records.

My question, hence, is can/will Sonic do this, and, if so, what's the next step down that path?

And, no, I'm not convinced I've gotten all the details straight ...

Thanks,

Richard
by augie » Thu Apr 04, 2013 5:26 pm
We have never done that, and I have no idea if we could accomplish API access for you.

Send me an e-mail ( augie@corp.sonic.net ) , and I will do some digging.
2 posts Page 1 of 1

Who is online

In total there are 16 users online :: 0 registered, 0 hidden and 16 guests (based on users active over the past 5 minutes)
Most users ever online was 999 on Mon May 10, 2021 1:02 am

Users browsing this forum: No registered users and 16 guests